Checkout security has moved from the card to the customer
Most card fraud in the UK no longer happens at the till. It has followed shoppers online, into the remote, card-not-present transactions that make up the bulk of everyday spending, where a stolen card number is worth far more to a criminal than a physical card ever was.
Industry fraud data compiled by UK Finance has tracked that shift for years: as chip-and-PIN closed the door on counterfeit cards in shops, losses migrated to the channels where the cardholder is not physically present.
Subscribe to TRBThe response from the payments industry has been a quiet but fundamental change in what “security” means at the point of sale. For decades the thing being protected was the card and its number. The newer model protects something else: proof that the person authorising a payment is who they claim to be. The card, increasingly, is beside the point.
From protecting the card to verifying the person
The mechanism behind that change is tokenisation. When a card is added to a phone or wallet app, the real 16-digit primary account number is not stored on the device and is never handed to the retailer. In its place sits a token, a separate device-specific number defined under the EMV payment tokenisation specification that the card networks maintain. Each transaction is authorised with that token plus a one-time cryptogram, so intercepting one exchange yields nothing that can be replayed against another.
The distinction matters because it is not the same as encryption. Encrypted card data can still be decrypted if the keys are compromised. A token has no underlying value to unlock in the first place. A retailer that is breached, or a database that leaks, exposes a string that is useless anywhere else. The actual card details never entered the merchant’s systems to begin with, which also shrinks the scope of what a business has to secure under card-industry data rules.
Why a glance now counts as security
Tokenisation solves the storage problem. Biometrics solve the authentication one. A payment made through a mobile wallet such as Apple Pay is released only after the device confirms its owner through Face ID, a fingerprint or a passcode: something the customer is, combined with something they have.
That combination does more than speed things up. Under Strong Customer Authentication, the two-factor requirement the Financial Conduct Authority enforces on electronic payments, most online transactions must be verified by at least two independent elements drawn from separate categories: knowledge, possession and inherence. On-device biometrics clear that test without bouncing the shopper to a bank’s one-time-passcode screen, the step where a large share of online baskets are abandoned. For a retailer, that is the rare control that reduces fraud exposure and cart abandonment at the same time.
The model has spread well beyond the high street
What began as a way to pay in shops has become the default across remote commerce. Because the real card number is never shared with the merchant, tokenised wallets have taken hold in higher-risk online sectors too. A growing number of online gaming sites now list it among their accepted payment methods, keeping card data off the operator’s servers while still clearing the age and identity checks their licences demand.
The pattern repeats wherever a transaction is remote, recurring or high in value, in subscriptions, travel and marketplace platforms. In each case the appeal is the same: a token the business can safely store, paired with an authentication step the business never has to see or handle itself. Sectors that carry the heaviest verification burden have tended to adopt first, precisely because the model lets them meet strict checks without becoming custodians of the sensitive data those checks would otherwise generate.
What it means for retailers
For retailers, the shift reframes an old trade-off. Friction and security were once assumed to move together: more checks meant more safety and more abandoned baskets. Tokenised, biometric payments weaken that link, offering stronger authentication and a faster checkout at once. The businesses seeing the benefit are those treating the wallet as a first-class payment route rather than a bolt-on, as earlier moves such as contactless and Tap to Pay already signalled.
The counter-pressure is dependence. Handing authentication to a handful of device makers concentrates much of the payment journey in their hands, a concern already visible in the debate over how digital wallets compare with traditional payment routes. Retailers gain security they no longer have to manage themselves, but they also cede a measure of control over the checkout to platforms they do not own.
Where this goes next is already visible in passkeys, the same biometric-and-device logic applied to logins rather than payments, and in early trials of agentic checkout, where software completes purchases on a shopper’s behalf. Both push in the direction the card has been travelling for a decade: the thing being verified is no longer the number printed on a piece of plastic, but the person, and the device, standing behind it.


